Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

SUSE Linux 11-SP4: Advisory ID 2017:1632-1 Critical Tomcat6 Remote Exec

suse
Calendar Grey June 21, 2017
Dist Suse Esm H88
A new patch for tomcat6 has been released addressing 10 significant vulnerabilities that include information exposure and potential remote code execution risks.
An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata ...

Summary

This update for tomcat6 fixes the following issues: Tomcat was updated to version 6.0.53: The full changelog is: http://tomcat.apache.org/tomcat-6.0-doc/changelog.html Security issues fixed: - CVE-2017-5647: A bug in the handling of pipelined requests could lead to information disclosure (bsc#1036642) - CVE-2016-8745: Regression in the error handling methods could lead to information disclosure (bsc#1015119) - CVE-2016-8735: Remote code execution vulnerability in JmxRemoteLifecycleListener (bsc#1011805) - CVE-2016-6816: HTTP Request smuggling vulnerability due to permitting invalid character in HTTP requests (bsc#1011812) - CVE-2016-6797: Unrestricted Access to Global Resources (bsc#1007853) - CVE-2016-6796: Manager Bypass (bsc#1007858)

References

#1007853 #1007854 #1007855 #1007857 #1007858

#1011805 #1011812 #1015119 #1033448 #1036642

#988489

Cross- CVE-2016-0762 CVE-2016-5018 CVE-2016-5388

CVE-2016-6794 CVE-2016-6796 CVE-2016-6797

CVE-2016-6816 CVE-2016-8735 CVE-2016-8745

CVE-2017-5647

Affected Products:

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Point of Sale 11-SP3

https://www.suse.com/security/cve/CVE-2016-0762.html

https://www.suse.com/security/cve/CVE-2016-5018.html

https://www.suse.com/security/cve/CVE-2016-5388.html

https://www.suse.com/security/cve/CVE-2016-6794.html

https://www.suse.com/security/cve/CVE-2016-6796.html

https://www.suse.com/security/cve/CVE-2016-6797.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:1632-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here